All Hackers Go To Cloud
All Hackers Go To Cloud ☁️💻 During the investigation of an incident in a fully encrypted infrastructure, we identified an autonomous web server hosting the clie…
All Hackers Go To Cloud ☁️💻 During the investigation of an incident in a fully encrypted infrastructure, we identified an autonomous web server hosting the clie…
HTML attachments as a phishing tool 🤑 Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting wit…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
In addition to the previous post, we want to talk about some other potential ways of detecting the execution of malicious code in the "1C" system 😳 • First, if…
Following the 1C_Shell trail. Investigating attacks using the event log 🐾 In one of our previous posts, we wrote about detecting attacks on the 1C system in whi…
🛡 Puma: how a rootkit provides covert SSH access through stealthy key substitution Continuing our story about the activities of the ExCobalt group and its new t…
(Ex)Cobalt == (Ex)Carbanak 🤔 Since the beginning of 2025, the PT ESC team has observed a rise in the number of attacks using the SshDoor backdoor. Russian gover…
🐾 Following in Puma's Footsteps: How to Detect a Rootkit Through Its Own Interface Today, our review covers a technically interesting and multifunctional Linux…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
Graphics with a Surprise: When Vectors Hide Malicious Code 🤨 In this post, we will examine an example of a phishing email in which malicious content was deliver…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
Net group "babyk" /add During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows…